2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5715 | — | — | 7.0% | Jan 16, 2018 | phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). |
| CVE-2018-1000004 | — | — | 3.6% | Jan 16, 2018 | In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound sys... |
| CVE-2018-5714 | — | — | 0.4% | Jan 16, 2018 | In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2018-5713 | — | — | 1.1% | Jan 16, 2018 | In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2018-5370 | — | — | 2.2% | Jan 16, 2018 | BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI. |
| CVE-2018-5330 | — | — | 1.8% | Jan 16, 2018 | ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flo... |
| CVE-2018-5706 | — | — | 1.0% | Jan 16, 2018 | An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give ... |
| CVE-2018-5712 | — | — | 80.3% | Jan 16, 2018 | An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is... |
| CVE-2018-5711 | — | — | 13.4% | Jan 16, 2018 | gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.... |
| CVE-2018-5710 | — | — | 1.8% | Jan 16, 2018 | An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL"... |
| CVE-2018-5709 | — | — | 2.1% | Jan 16, 2018 | An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/d... |
| CVE-2018-5704 | — | — | 4.7% | Jan 16, 2018 | Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444,... |
| CVE-2018-5329 | — | — | 0.5% | Jan 15, 2018 | ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated p... |
| CVE-2018-5328 | — | — | 1.3% | Jan 15, 2018 | ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticat... |
| CVE-2018-5702 | — | — | 12.1% | Jan 15, 2018 | Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con... |
| CVE-2018-5479 | — | — | 2.1% | Jan 15, 2018 | FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its sear... |
| CVE-2018-5700 | — | — | 3.3% | Jan 14, 2018 | Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a net... |
| CVE-2018-5688 | — | — | 3.3% | Jan 14, 2018 | ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in ... |
| CVE-2018-5698 | — | — | 1.0% | Jan 14, 2018 | libreadstat.a in WizardMac ReadStat 0.1.1 has a heap-based buffer over-read via an unterminated string. |
| CVE-2018-5697 | — | — | 1.0% | Jan 14, 2018 | Icy Phoenix 2.2.0.105 allows SQL injection via an unapprove request to admin_kb_art.php or the order parameter to admin_... |
| CVE-2018-5696 | — | — | 1.5% | Jan 14, 2018 | The iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` p... |
| CVE-2018-5695 | — | — | 1.2% | Jan 14, 2018 | The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-a... |
| CVE-2018-5694 | — | — | 2.4% | Jan 14, 2018 | The callforward module in User Control Panel (UCP) in Nicolas Gudino (aka Asternic) Flash Operator Panel (FOP) 2.31.03 a... |
| CVE-2018-5693 | — | — | 0.4% | Jan 14, 2018 | The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /va... |
| CVE-2018-5692 | — | — | 0.7% | Jan 14, 2018 | Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.ph... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now